The current state of security for autonomous agents in the cloudSecurity controls and best practices for architecting the runtime: isolation, identity, egress, credentials, and a tool broker outside the model.Sep 20, 2026·13 min read
From Finding Bugs to Fixing Them: How Far Has AI Vulnerability Remediation Come?Aug 26, 2026·13 min read
Security Reviews of Enterprise AI Systems in 2026Lessons from Recent Disclosures and Real-World ReviewsAug 25, 2026·16 min read
How Frontier Model Agents Accidentally Do Offensive SecurityOpenAI - Hugging Face - Model evaluation security incidentAug 16, 2026·12 min read
Adapting Matt Pocock's grill-with-docs skill to create a Threat Modeling skillI was working on a new app and came across Matt Pocock's /grill-with-docs skill that works as a structured interrogation tool that stress-tests your plan against your project's domain model, cross-refMay 23, 2026·5 min read
One MCP Server Over Six Scanners: Security Posture as a Queryable APIBuilding a normalised finding schema across six scanners and an MCP layer that lets developers, security engineers, and CI pipelines query, fix, and verify vulnerabilities, all from the tools they already have open.May 19, 2026·33 min read
Pipeline Security and Supply Chain Risk: Closing the Gap Between AppSec and CloudSecWhy the assumption that CI/CD is a trusted internal tool has already cost organisations dearlyMay 19, 2026·12 min read
Attacking Kubernetes: Offensive Recon and Attack Path Analysis with CDK, Kubehound, and KubescapePart 1 - Lab setup, attacker simulation, and finding exploitable misconfigurationsMay 14, 2026·12 min read